Need help? Support
BITCOIN
Tether Dominance USDT.D

iPhone spyware targets imToken crypto wallet data

Published 525 words 3 min read

TLDR

New iPhone spyware variants can scan for crypto wallets and specifically target imToken app data on already compromised devices, raising serious risks for affected users funds and privacy.

  1. Security researchers have documented P7 DarkSword and related iOS exploit chains that scan for wallet apps and extract data from imToken on infected iPhones.
  2. The malware can harvest wallet files, Keychain entries, photos and notes, potentially exposing recovery phrases or credentials, but confirmed crypto theft via this variant has not yet been reported.
  3. Updating iOS, treating any suspicious device as untrusted, and moving funds to wallets created on a clean device are key defenses for imToken and other wallet users.

Deep Dive

1. What The Spyware Is Doing

Cybersecurity firm iVerify and others describe P7 DarkSword as an upgraded iPhone spyware variant that runs on devices already compromised by an exploit chain, not as a new universal iOS zero?day.

On infected phones, a wallet_scan function searches for installed crypto wallets, and a wallet_extract command targets wallet-related files from imToken, marking that app as a named data source in the malware configuration.

Separate reporting on the DarkSword/Coruna toolkit shows the same ecosystem of exploits being used to deploy malware that targets multiple wallets, including imToken, Coinbase, MetaMask, Trust Wallet, Phantom, Exodus, Bitpie and OKX, and scans for recovery phrases in photos and notes.

2. How It Threatens Wallet Data

Once on the device, P7 DarkSword can contact attacker servers every 15 seconds for instructions and exfiltrate sensitive data such as Apple Keychain items, imToken files, Apple Notes databases, photos and selected app data.

This mix of data may contain account identifiers, locally cached credentials or even BIP39 recovery phrases, which would, in principle, allow attackers to recreate wallets and move funds without physical access to the phone.

Researchers stress that finding wallet files does not automatically mean private keys are compromised, and so far they have not confirmed specific cases of cryptocurrency theft or documented losses linked directly to this variant.

What this means

The main risk is that once your iPhone is deeply compromised, any wallet or recovery data stored on it should be treated as potentially exposed, regardless of which app you use.

3. What ImToken Users Should Do

The exploit chains behind DarkSword targeted specific iOS versions, and Apple has issued security updates that close the known vulnerabilities, so running the latest iOS version meaningfully reduces exposure.

If your iPhone shows unusual behavior, has unknown configuration profiles or mobile device management (MDM) installed, or you suspect compromise, assume your imToken data might be exposed and migrate funds to a new wallet created on a different, trusted device.

Avoid storing seed phrases or private keys in photos, screenshots or notes; use offline storage and consider hardware wallets for larger balances, pairing them with a well?maintained, updated phone only as a signing interface.

Conclusion

The new iPhone spyware targeting imToken data highlights a familiar pattern: once an attacker owns the device, wallet security is largely undermined by operating?system compromise. Keeping iOS fully updated, treating suspicious phones as untrusted and separating long?term savings into more hardened setups can sharply reduce the chance that an infection translates into actual crypto losses.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top